IP Library › Granted Patent US 12,265,855
Granted Patent B2
US 12,265,855 · App. 17/811,628 · Granted Apr 1, 2025

Infrastructure for deploying a security information and event management application on a container platform

Inventors: Elias S. Alagna (San Jose, CA); Christopher Michael Crawford (Hoover, AL); Swami Viswanathan (Santa Clara, CA); Richard B. Peterson (Tustin, CA); Rohan Jayaraj (Santa Clara, CA); Randy Thomasson (Ilwaco, WA); Alok Daipuria (Santa Clara, CA)
Assignee: Hewlett Packard Enterprise Development LP
G06F9/505
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,265,855
App. No.
17/811,628
Granted
Apr 1, 2025
Kind
B2
Abstract

Embodiments described herein are generally directed to a containerized application software deployment architecture. According to an example, a system includes multiple hosts that are part of aa stretch cluster spanning multiple data centers. Each of the hosts include a processing resource, a memory, and a storage device. Each host of a first subset of the multiple hosts runs multiple containerized instances of a component of a Security Information and Event Management (SIEM) application within respective containers. At least one host of the multiple hosts is separate from the first subset and is dedicated to running at least one containerized ingress gateway application operable to load balance requests directed to the SIEM application among the multiple containerized instances running on the first subset of hosts.

Claims (18)

1. A method comprising:

configuring a subset of a plurality of hosts that are part of a stretch cluster spanning a plurality of data centers as service mesh hosts for hosting a service mesh;

executing a command on each host of the subset of the plurality of hosts to preclude the subset of the plurality of hosts from executing portions of a Security Information and Event Management (SIEM) application other than a plurality of containerized ingress gateways;

installing the plurality of containerized ingress gateways on the subset of the plurality of hosts, wherein each host of the subset of the plurality of hosts has installed at least one of the plurality of containerized ingress gateways;

maintaining, by an ingress gateway of the plurality of containerized ingress gateways running on the subset of the plurality of hosts that are the part of the stretch cluster spanning the plurality of data centers, route rules and policies for routing traffic to a plurality of virtual services associated with the SIEM application that are available within the stretch cluster spanning the plurality of data centers;

receiving, by the ingress gateway, traffic indicative of a particular virtual service of the plurality of virtual services, wherein:

the particular virtual service comprises an indexer service,

a plurality instances of an indexer component of the indexer service are deployed on a host, of the plurality of hosts, that is separate from the subset of the plurality of hosts, and

a quantity of the plurality of instances of the indexer component deployed on the host is selected to increase an ingestion rate of the host; and

routing, by the ingress gateway, the traffic to an instance of the plurality of instances of the indexer component based on one of more of a topology of the stretch cluster, and the route rules and policies.

2. The method of claim 1 , wherein the traffic comprises a Hypertext Transfer Protocol (HTTP) request including a host request header containing information indicative of the particular virtual service, and wherein said routing comprises routing the HTTP request to an instance of the particular virtual service based on the host request header.

3. The method of claim 2 , wherein the information indicative of the particular virtual service comprises a Fully Qualified Domain Name (FQDN).

4. The method of claim 2 , wherein the HTTP request is generated by a source system based on a Domain Name System (DNS) response received from a network load balancer that load balances requests relating to the SIEM application among the plurality of containerized ingress gateways.

5. The method of claim 1 , wherein multiple instances of the plurality of virtual services are running on each host of a second subset of the plurality of hosts.

6. The method of claim 1 , wherein said routing comprises selecting an instance of the plurality of instances of the indexer component based further on a locality-based load balancing algorithm.

7. The method of claim 1 , wherein each ingress gateway of the plurality of containerized ingress gateways exposes a fixed Internet Protocol (IP) address.

8. The method of claim 1 , wherein the indexer service is operable to index large volume machine-generated data.

9. The method of claim 1 , wherein another virtual service of the plurality of virtual services is operable to direct a received search request to a set of search peers and return a result representing a merger of results provided by the set of search peers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2022
From: ALAGNA, ELIAS S.; CRAWFORD, CHRISTOPHER MICHAEL; VISWANATHAN, SWAMI; PETERSON, RICHARD B.; JAYARAJ, ROHAN; THOMASSON, RANDY; DAIPURIA, ALOK
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 060470/0374 →
Continuity (2)
Continuation In Part 17074526 · Oct 19, 2020
Related Publication 20220342707A1 · Oct 27, 2022
References Cited (51)
US 9830175B1 · Wagner · 2017 [cited by examiner]
US 10083057B1 · Currie et al. · 2018 [cited by applicant]
US 10567288B1 · Mutnuru · 2020 [cited by examiner]
US 10812366B1 · Berenberg et al. · 2020 [cited by applicant]
US 11237813B1 · Chen · 2022 [cited by examiner]
US 11388234B2 · Alagna · 2022 [cited by examiner]
US 11449280B1 · Dhuse · 2022 [cited by examiner]
US 12010186B2 · Yang · 2024 [cited by examiner]
US 12079255B1 · Patel · 2024 [cited by examiner]
US 12169652B2 · Dhuse · 2024 [cited by examiner]
US 20130212240A1 · Thornewell · 2013 [cited by examiner]
US 20140068611A1 · McGrath et al. · 2014 [cited by applicant]
US 20140092906A1 · Kandaswamy · 2014 [cited by examiner]
US 20150220080A1 · Nixon et al. · 2015 [cited by applicant]
US 20160321352A1 · Patel · 2016 [cited by examiner]
US 20170126469A1 · Liang et al. · 2017 [cited by applicant]
US 20180096979A1 · Pappu et al. · 2018 [cited by applicant]
US 20180137174A1 · Cahana et al. · 2018 [cited by applicant]
US 20180218045A1 · Pal et al. · 2018 [cited by applicant]
US 20180287891A1 · Shaw · 2018 [cited by examiner]
US 20180367609A1 · Ozkan · 2018 [cited by examiner]
US 20190052532A1 · Chen et al. · 2019 [cited by applicant]
US 20190199540A1 · Robitzsch · 2019 [cited by examiner]
US 20190354637A1 · Ivancich et al. · 2019 [cited by applicant]
US 20200097204A1 · Sato et al. · 2020 [cited by applicant]
US 20200314173A1 · Pahwa et al. · 2020 [cited by applicant]
US 20210067489A1 · Jayawardena · 2021 [cited by examiner]
US 20220004381A1 · Myers et al. · 2022 [cited by applicant]
US 20220191168A1 · Snehashis · 2022 [cited by examiner]
US 20220357995A1 · Moussaoui · 2022 [cited by examiner]
US 20220374267A1 · Katyal · 2022 [cited by examiner]
US 20220385735A1 · Yang · 2022 [cited by examiner]
US 20230305876A1 · Sharma · 2023 [cited by examiner]
Ali et al., “Container Storage Interface (CSI) for Kubernetes GA”, Kubernetes, available online at <https://kubernetes.io/blog/2019/01/15/container-storage-interface-ga/>, Jan. 15, 2019, 6 pages. [cited by applicant]
Edureka, “Splunk Architecture: Tutorial on Forwarder, Indexer and Search Head”, available online at <https://web.archive.org/web/20191113013802/https://www.edureka.co/blog/splunk-architecture/>, May 22, 2019, 8 pages. [cited by applicant]
Hewlett Packard Enterprise, “HPE Ezmeral Container Platform”, Aug. 3, 2020, 15 pages. [cited by applicant]
Hewlett Packard Enterprise, “HPE ProLiant DL380 Gen10 Server”, Oct. 1, 2020, 95 pages. [cited by applicant]
Hewlett Packard Enterprise, “HPE Scalable Object Storage with Scality Ring”, Solution brief, Jun. 2019, Rev. 4, 2 pages. [cited by applicant]
Intel, “Introducing Intel (Registered) QLC 3D NAND Technology”, Solution Brief, Sep. 2019, 4 pages. [cited by applicant]
Istio, “The Istio Service Mesh”, available online at <https://istio.io/v1.6/docs/concepts/what-is-istio/>, Aug. 21, 2020, 4 pages. [cited by applicant]
Istio, “Traffic Management”, available online at <https://web.archive.org/web/20200810084914/https://istio.io/latest/docs/concepts/traffic-management/>, Aug. 10, 2020, 15 pages. [cited by applicant]
OpenEBS Docs, “Container Attached Storage (CAS)”, available online at <https://web.archive.org/web/20200815140026/https://docs.openebs.io/docs/next/cas.html>, Aug. 15, 2020, 5 pages. [cited by applicant]
OpenEBS Docs, “Welcome to OpenEBS Documentation”, available online at <https://web.archive.org/web/20190330081311/https://docs.openebs.io/>, Mar. 30, 2019, 3 pages. [cited by applicant]
Splunk, “About search head clustering”, available online at <https://docs.splunk.com/Documentation/Splunk/8.1.0/DistSearch/AboutSHC#>, Sep. 23, 2015, 2 pages. [cited by applicant]
Splunk, “An Insider's Guide to Splunk on Containers and Kubernetes”, available online at <https://www.splunk.com/en_us/blog/it/an-insider-s-guide-to-splunk-on-containers-and-kubernetes.html>, May 8, 2019, 6 pages. [cited by applicant]
Splunk, “Indexer”, available online at <https://web.archive.org/web/20181119231629/http://docs.splunk.com/Splexicon:Indexer>, Nov. 29, 2018, 12 pages. [cited by applicant]
Splunk, “Indexes, indexers, and indexer clusters”, available online at <https://web.archive.org/web/20201129083259/https://docs.splunk.com/Documentation/Splunk/8.1.0/Indexer/Aboutindexesandindexers>, Sep. 3, 2020, 4 pag… [cited by applicant]
Splunk, “Introducing the Splunk Operator for Kubernetes”, available online at <https://www.splunk.com/en_us/blog/platform/introducing-the-splunk-operator-for-kubernetes.html>, Nov. 22, 2019, 3 pages. [cited by applicant]
Splunk, “Multisite indexer cluster architecture”, available online at <https://web.archive.org/web/20201129083809/https://docs.splunk.com/Documentation/Splunk/8.1.0/Indexer/Multisitearchitecture>, Oct. 15, 2020, 5 pages. [cited by applicant]
Splunk, “Search head clustering architecture”, available online at <https://web.archive.org/web/20201202103305/https://docs.splunk.com/Documentation/Splunk/8.1.0/DistSearch/SHCarchitecture>, Oct. 16, 2020, 7 Pages. [cited by applicant]
Splunk, “Search Head”, available online at <https://web.archive.org/web/20180202113300/https://docs.splunk.com/Splexicon:Searchhead>, Feb. 2, 2018, 12 pages. [cited by applicant]